Summary | ZeroBOX

csrss00.exe

Malicious Library UPX PE32 PE File DLL
Category Machine Started Completed
FILE s1_win7_x6403_us July 12, 2023, 5:23 p.m. July 12, 2023, 5:36 p.m.
Size 420.9KB
Type PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5 601f2b22a16a96c9ddaae24e2c5611f2
SHA256 8c63c1e28683c7aa90cb40df346fe1d5dbc3b2bd994cd883cd7e551518486098
CRC32 A6036723
ssdeep 6144:kC2guh2RGxfWgrfXQi12xMhtj3+z0N+Y9uVza:fY2sxuUfXB2xMfbsS+YsVza
Yara
  • UPX_Zero - UPX packed file
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section .ndata
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 840
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x10004000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 840
region_size: 40902656
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x03260000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0xffffffff
1 0 0
file C:\Users\test22\AppData\Local\Temp\nshC290.tmp\System.dll
Time & API Arguments Status Return Repeated

SetFileAttributesW

file_attributes: 2 (FILE_ATTRIBUTE_HIDDEN)
filepath_r: C:\Windows\resources\0409\denitrified\alleging\Lightheadedly.sko
filepath: C:\Windows\resources\0409\denitrified\alleging\Lightheadedly.sko
0 0

SetFileAttributesW

file_attributes: 2 (FILE_ATTRIBUTE_HIDDEN)
filepath_r: C:\Windows\resources\0409\denitrified\alleging\Lightheadedly.sko
filepath: C:\Windows\resources\0409\denitrified\alleging\Lightheadedly.sko
0 0

SetFileAttributesW

file_attributes: 2 (FILE_ATTRIBUTE_HIDDEN)
filepath_r: C:\Windows\resources\0409\denitrified\alleging\Lightheadedly.sko
filepath: C:\Windows\resources\0409\denitrified\alleging\Lightheadedly.sko
0 0

SetFileAttributesW

file_attributes: 2 (FILE_ATTRIBUTE_HIDDEN)
filepath_r: C:\Windows\resources\0409\denitrified\alleging\Lightheadedly.sko
filepath: C:\Windows\resources\0409\denitrified\alleging\Lightheadedly.sko
0 0

SetFileAttributesW

file_attributes: 2 (FILE_ATTRIBUTE_HIDDEN)
filepath_r: C:\Windows\resources\0409\denitrified\alleging\Lightheadedly.sko
filepath: C:\Windows\resources\0409\denitrified\alleging\Lightheadedly.sko
0 0

SetFileAttributesW

file_attributes: 2 (FILE_ATTRIBUTE_HIDDEN)
filepath_r: C:\Windows\resources\0409\denitrified\alleging\Lightheadedly.sko
filepath: C:\Windows\resources\0409\denitrified\alleging\Lightheadedly.sko
0 0
file C:\ProgramData\Microsoft\Windows\Templates\patronymers\heftiness.lnk
file C:\Users\test22\AppData\Roaming\Microsoft\Windows\Templates\patronymers\heftiness.lnk
file C:\Windows\Fonts\arklngdernes\Lowly\brunch\Brugerskrms.lnk
file C:\Users\test22\AppData\Local\Temp\nshC290.tmp\System.dll
Time & API Arguments Status Return Repeated

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Allistir84\ideologiserende\kavaleris\sikkerhedsforvaringernes
2 0

RegOpenKeyExA

regkey_r: Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
base_handle: 0x80000001
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\theophrastaceous
2 0
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Makoob.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.Generic.34016020
FireEye Trojan.Generic.34016020
McAfee Artemis!601F2B22A16A
ALYac Trojan.Generic.34016020
Malwarebytes Malware.AI.3480413814
VIPRE Trojan.Generic.34016020
Sangfor Trojan.Win32.Makoob.Vxxg
K7AntiVirus Trojan ( 005903451 )
Alibaba Trojan:Win32/Makoob.03e3ddea
K7GW Trojan ( 005903451 )
CrowdStrike win/malicious_confidence_100% (W)
Arcabit Trojan.Generic.D2070B14
Symantec ML.Attribute.HighConfidence
ESET-NOD32 NSIS/Injector.ASH
Cynet Malicious (score: 99)
Kaspersky HEUR:Trojan.Win32.Makoob.gen
BitDefender Trojan.Generic.34016020
Avast Win32:Evo-gen [Trj]
Tencent Win32.Trojan.FalseSign.Vdkl
Emsisoft Trojan.Generic.34016020 (B)
F-Secure Trojan.TR/Makoob.uzzxj
DrWeb Trojan.Inject4.58823
TrendMicro Trojan.Win32.GULOADER.YXDGCZ
McAfee-GW-Edition Artemis!Trojan
Sophos Mal/Generic-S
Avira TR/Makoob.uzzxj
MAX malware (ai score=80)
Gridinsoft Trojan.Win32.Agent.cl
Microsoft Program:Win32/Wacapew.C!ml
ZoneAlarm HEUR:Trojan.Win32.Makoob.gen
GData Trojan.Generic.34016020
Google Detected
AhnLab-V3 Trojan/Win.GuLoader.C5449503
Cylance unsafe
Panda Trj/Chgt.AD
TrendMicro-HouseCall Trojan.Win32.GULOADER.YXDGCZ
Ikarus Trojan.NSIS.Guloader
Fortinet W32/Trojan_Win32_GULOADER.YXDGCZ
AVG Win32:Evo-gen [Trj]
DeepInstinct MALICIOUS